ZeroHour

CVE-2026-88285

niche1

Missing authentication in GeoVision GV-LPC2211 PTZ control service

CVSS 3.1
9.4 critical
EPSS
Published
()
Modified
AI analysis

GeoVision's GV-LPC2211 license plate capture camera running firmware V1.13 exposes its PTZ (pan-tilt-zoom) control service over the network without any authentication (CWE-306, Missing Authentication for Critical Function). Any remote client that can reach the camera on the network can connect directly to this service to read PTZ status and issue PTZ movement or raw serial commands, with no credentials, user interaction, or special conditions required. An attacker gains full control of the camera's pan/tilt/zoom behavior and can drive any device connected to the camera's serial port, consistent with the 9.4 CVSS score's high integrity and availability impact and limited confidentiality impact. Affected users are operators of GV-LPC2211 cameras on firmware V1.13 whose PTZ service is reachable from untrusted networks; the available data specifies no other version ranges and no fixed version. There are no known public proofs of concept, the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: No fixed firmware version is specified in the available data, so check GeoVision advisories for GV-LPC2211 firmware updates and upgrade when a patched release is published. In the meantime, restrict network access to the camera's PTZ control service via firewall ACLs or VLAN segmentation and avoid exposing it directly to the internet, since any reachable client can command PTZ and raw serial traffic. Operators with peripherals attached to the camera's serial port should treat those devices as reachable by unauthenticated network clients and monitor for unexpected PTZ movement or serial activity.

Affected
GeoVision GV-LPC2211 license plate capture cameraV1.13 (version cited in the advisory; full affected range and fixed version not specified in the data)
Estimated exposure
niche≈1,000–10,000 units worldwide (single-model specialty LPR camera; no public install counts or scan data) — The GV-LPC2211 is one specific license-plate-capture camera model from a mid-sized CCTV vendor, typically deployed per site (parking facilities, tolling, traffic enforcement) rather than at consumer scale, and no active-install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

In the news

No ingested article mentions this CVE yet.